Replies: 2 comments
|
We have not tested older versions and therefore don't know which older versions work. |
|
Looks like it starts breaking at 0.061. |
|
We have not tested older versions and therefore don't know which older versions work. |
|
Looks like it starts breaking at 0.061. |
Uh oh!
There was an error while loading. Please reload this page.
Hello,
Thanks for Mojolicious, including the new support for using CryptX to generate secure default session secrets. I'm looking at backporting that support to older Mojolicious in order to address CVE-2024-58135 in older releases of Debian.
Commit c820715 adding the support specifies that CryptX 0.080 is required. @kraih, are you sure it's required? Looking at the Changes for CryptX, it doesn't seem like the fixes in that release are essential to the new functionality.
Would it be possible for the reasons for requiring 0.080 to be expanded upon, and possibly the dependency bound weakened?
Thanks.
All reactions